Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia: 2020-0169 Moderate: krb5-appl Heap Corruption Advisory

mageia
Calendar Grey April 15, 2020
Dist Mageia Esm H88
Mageia releases critical patches for krb5-appl packages addressing vulnerabilities related to information leakage and heap overflow, potentially enabling remote code execution.

Updated krb5-appl packages fix security vulnerability: A vulnerability was found where incorrect bounds checks in the telnet server’s (telnetd) handling of short writes and ur...

Summary

Updated krb5-appl packages fix security vulnerability:
A vulnerability was found where incorrect bounds checks in the telnet server’s (telnetd) handling of short writes and urgent data, could lead to information disclosure and corruption of heap data. An unauthenticated remote attacker could exploit these bugs by sending specially crafted telnet packets to achieve arbitrary code execution in the telnet server (CVE-2020-10188).

References

- https://bugs.mageia.org/show_bug.cgi?id=26451

- https://access.redhat.com/errata/RHSA-2020:1349

- https://www.cve.org/CVERecord?id=CVE-2020-10188

Resolution

SRPMS

- 7/core/krb5-appl-1.0.3-10.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 15 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0169.html
Type: security
CVE: CVE-2020-10188

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here